V. CLOUD SECURITY FRAMEWORK ARCHITECTURE
Our framework architecture consists of three main layers: a
management layer, an enforcement layer, and a feedback
layer. These layers, shown in Figure 3, represent the
realization of the ISMS phases described in section II.
Management layer. This layer is responsible for capturing
security specifications of the CPs, SPs, and CCs. It consists
of: (a) The security categorization service used by the
hosted services’ tenants to specify security categorization of
their information maintained by the cloud services; (b) The
collaborative risk assessment service where all the cloud
platform stakeholders participate in the risk assessment
process with the knowledge they posses. (c) The security
controls manager service is used to register security
controls, their mappings to the FISMA security controls’
templates, and their log files structure and locations. (d) The